Skip to main content

Self-Service Identity

Identity solution

Let users complete identity tasks safely without waiting for the helpdesk—while keeping verification, account actions, and notifications under NIM control.

At a glance

NIM self-service supports verified password reset and onboarding workflows without sending users their credentials. Password reset verifies the person before allowing a reset; onboarding verifies the owner of a prepared account, lets them choose a first password, and activates access.

Before publishing: provide secure HTTPS access, current contact data for verification, and working email or SMS delivery. Test the complete end-user journey with a safe record before making either workflow available to users.

Choose the experience

Both experiences need secure HTTPS access, reliable contact data, and configured notification delivery. Use email settings and, where required, SMS settings before testing with users.

Choose the right self-service pattern

User needRecommended NIM experienceRequired control
A user has forgotten a passwordSelf-service password resetVerify the person before the reset, then enforce the target password policy.
A new user needs to activate a prepared accountOnboardingVerify the prepared account owner, let the user choose the first password, and activate access without disclosing credentials.
An approved user must request or perform another defined identity taskNIM AppGrant access only to the approved users or groups and configure only the actions the form requires.

Use a user-facing workflow when a person must provide information, prove control of a contact method, make a choice, or receive a controlled exception. Use a scheduled mapping, role, or job when trusted source data already determines the change and no user interaction is required.

Test before publishing

  1. Confirm the published URL is available through HTTPS and that the intended users can reach it.
  2. Verify the email or SMS delivery path with a safe test contact method.
  3. Run the complete journey with a safe record, including verification, form input, target-system action, and resulting notification.
  4. Confirm the target account, password, or access state has the intended result.
  5. Check that an unauthorized or unrelated user cannot access the experience or complete the action.

If a self-service action does not produce the expected target change, review its configured action and then use Troubleshoot NIM provisioning failures to check the related filter, mapping, connector access, and job result.